Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.231exploits catalogados
35.420CVEs con explotación pública
24.695probados en laboratorio
22.266 exploits
Referência
CVE-2010-5043
SQL injection vulnerability in the DJ-ArtGallery (com_djartgallery) component 0.9.1 for Joomla! allows remote authentica
23RIESGO
abrir
Referência
CVE-2007-1297
SQL injection vulnerability in view_profile.php in AJDating 1.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
Referência
CVE-2026-10300
SGLang Inference HTTP Endpoint lora_manager.py assertion
33RIESGO
abrir
ReferênciaVexDay Proof
Rigter Portal System (RPS) 6.2 - Blind SQL Injection
CVE-2007-1293webappsphp
SQL injection vulnerability in Rigter Portal System (RPS) 6.2, when magic_quotes_gpc is disabled, allows remote attacker
23RIESGO
abrir
Referência
CVE-2018-12524
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /lib/ provi
23RIESGO
abrir
Referência
CVE-2026-15672
itsourcecode Electronic Judging System add_judges.php sql injection
33RIESGO
abrir
ReferênciaVexDay Proof
DivX Web Player 1.3.0 - 'npdivx32.dll' Remote Denial of Service
CVE-2007-1294doswindows
A certain ActiveX control in the DivXBrowserPlugin (npdivx32.dll) in DivX Web Player, as distributed with DivX Player 1.
23RIESGO
abrir
Referência
CVE-2021-47931
Exponent CMS 2.6 Multiple Vulnerabilities Stored XSS Authentication
33RIESGO
abrir
Referência
CVE-2026-10298
ggml-org whisper.cpp ggml.c whisper_model_load null pointer dereference
33RIESGO
abrir
ReferênciaVexDay Proof
AJ Classifieds 1.0 - 'postingdetails.php' SQL Injection
CVE-2007-1296webappsphp
SQL injection vulnerability in postingdetails.php in AJ Classifieds 1.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Referência
CVE-2026-10198
Assimp glTFImporter glTFImporter.cpp ImportMeshes null pointer dereference
33RIESGO
abrir
Referência
CVE-2026-10197
Assimp TF File glTF2Importer.cpp ImportEmbeddedTextures null pointer dereference
33RIESGO
abrir
Referência
CVE-2026-10193
OFCMS ComnController ComnController.java query sql injection
33RIESGO
abrir
Referência
CVE-2026-15669
louisho5 picobot exec Tool exec.go ExecTool.Execute os command injection
33RIESGO
abrir
Referência
CVE-2026-15668
louisho5 picobot web Tool web.go WebTool.Execute server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-15624
nextlevelbuilder GoClaw invoke Endpoint create_video_byteplus.go bytePlusDownloadVideo server-side request forgery
33RIESGO
abrir
Referência
CVE-2012-0394
The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers
60RIESGO
abrir
Referência
CVE-2012-0394
The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers
60RIESGO
abrir
Referência
CVE-2026-5337
Frontend File Manager Plugin <= 23.6 - Subscriber+ Arbitrary Download Access via IDOR
33RIESGO
abrir
Referência
CVE-2026-7679
YunaiV yudao-cloud OAuth2TokenServiceImpl.java getAccessToken improper authentication
33RIESGO
abrir
Referência
CVE-2026-7605
JeecgBoot uploadImgByHttpEndpoint CommonController.java HttpFileToMultipartFileUtil.downloadImageData server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-7603
JeecgBoot LoadFile Endpoint FileDownloadUtils.jav checkPathTraversalBatch server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-7602
JeecgBoot FillRuleUtil edit improper authorization
33RIESGO
abrir
Referência
CVE-2026-41462
ProjeQtor < 12.4.4 Unauthenticated SQL Injection via Login
48RIESGO
abrir
Referência
CVE-2026-7134
code-projects Online Lot Reservation System edithousepic.php unrestricted upload
33RIESGO
abrir
Referência
CVE-2026-7133
code-projects Online Lot Reservation System activity.php unrestricted upload
33RIESGO
abrir
Referência
CVE-2026-7132
code-projects Online Lot Reservation System download.php readfile path traversal
33RIESGO
abrir
Referência
CVE-2026-7131
code-projects Online Lot Reservation System loginuser.php sql injection
33RIESGO
abrir
Referência
CVE-2026-7130
SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
33RIESGO
abrir
Referência
CVE-2026-7129
SourceCodester Pharmacy Sales and Inventory System index.php cross site scripting
33RIESGO
abrir
anteriorpágina 437 / 743siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.